You can replace the certificate for a manager node or the manager cluster virtual IP (VIP) by making an API call.
After you install NSX-T Data Center, the manager nodes and cluster have self-signed certificates. To improve security, it is highly recommended that you replace the self-signed certificates with CA-signed certificates and that you use a different certificate for each node.
Prerequisites
Verify that a certificate is available in the NSX Manager. See Import a Certificate.